The US Cybersecurity and Infrastructure Security Agency (CISA) announced the retirement of its weekly vulnerability bulletin, effective September 28. This bulletin provided a summary of new vulnerabilities recorded each week, including product names, descriptions, publication dates, severity, CVSS scores, CVE identifiers, and patch information when available.
The discontinuation is part of CISA's pivot to a risk-based approach in vulnerability management. The previous bulletin, while comprehensive, listed thousands of vulnerabilities without specific guidance on prioritization, potentially leading to alert fatigue for defenders due to the sheer volume of flaws.
This move aligns with Binding Operational Directive (BOD) 26-04, which instructs federal agencies to prioritize vulnerabilities based on real-world risk factors, including evidence of exploitation and exposure, rather than relying solely on severity scores.
The broader cybersecurity industry has been transitioning away from sole reliance on CVSS metrics, which measure theoretical technical severity. Modern risk-based frameworks prioritize active exploits, threat actor interest, and exposure levels.
CISA's Known Exploited Vulnerabilities (KEV) catalog, introduced in 2021, has become a primary reference point for defenders. The KEV list focuses strictly on bugs with documented in-the-wild exploitation, offering actionable prioritization that static weekly bulletins could not provide.
Security operations centers (SOCs) that previously relied on the weekly bulletin for new vulnerability information may need to adjust their processes. CISA stated it will continue to provide risk-focused vulnerability information through its KEV catalog, alerts, and advisories.
✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →
One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.
One email a day. Unsubscribe in one click, any time.
Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.
▶ Play today's briefNew every morning, and the back catalogue is archived by date.
The US Cybersecurity and Infrastructure Security Agency (CISA) is discontinuing its weekly vulnerability bulletin on September 28. This change aligns with a broader shift towards prioritizing vulnerabilities based on real-world risk factors, such as active exploitation, rather than solely on severity scores.